CVE-2023-54326: Linux

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: misc: pci_endpoint_test: Free IRQs before removing the device In pci_endpoint_test_remove(), freeing the IRQs after removing the device creates a small race window for IRQs to be received with the test device memory already released, causing the IRQ handler to access invalid memory, resulting in an oops. Free the device IRQs before removing the device to avoid this issue.

Affected products

  • Linux Linux: from 4.19, before 4.19.291 (fixed in 4.19.291); from 4.20, before 5.4.251 (fixed in 5.4.251); from 5.5, before 5.10.188 (fixed in 5.10.188); from 5.11, before 5.15.121 (fixed in 5.15.121); from 5.16, before 6.1.40 (fixed in 6.1.40); from 6.2, before 6.4.5 (fixed in 6.4.5)

Published 2025-12-30. Last modified 2026-08-04.